Splunk Enterprise Security

500 Internal Server Error-Response Not Ready

garima_chauhan
Path Finder

Hi,

I have ES APP (v 2.4.1) installed on Splunk (v 5.0.5) on Windows machine.

Machine details-

Processor- 2 GHz
RAM -7.50GB
System Type- 64-bit OS

After installation and initial configuration of the ES App, when I try to login into Splunk or browse through the tabs(after logon), I get the following error:

500 Internal Server Error
ResponseNot Ready

However, after refreshing a number of times, I get the following:

An error occurred while rendering the page template.See web_service.log for more details.

After refreshing the page repeatedly, Splunk Web console is displayed but with a solid red bar either on top of the page or above/below the time chart. I have tried changing the SPLUNKD_CONNECTION_TIMEOUT = 60 instead of its default value of 30 in $SPLUNK_HOME\Python2.7\site_packages\splunk\rest_init_.py but it did not work.

Please suggest as to what could be wrong here and how to rectify it.

0 Karma
1 Solution

ShaneNewman
Motivator

Look at the login page. If it says SPLUNK_VERSION=UNKNOWN, then you need to bounce the entire server. If you have WS2003R2 64-bit, this will be a common occurrence for you. The Cache is filling up and the server is loosing connectivity with the domain server. You can confirm that this is the issue if you check the WMI logs and see a ubroker error.

View solution in original post

0 Karma

ShaneNewman
Motivator

Look at the login page. If it says SPLUNK_VERSION=UNKNOWN, then you need to bounce the entire server. If you have WS2003R2 64-bit, this will be a common occurrence for you. The Cache is filling up and the server is loosing connectivity with the domain server. You can confirm that this is the issue if you check the WMI logs and see a ubroker error.

0 Karma

garima_chauhan
Path Finder

The login page does not display SPLUNK_VERSION=UNKNOWN. The windows server I am using is WS2008R2 64 bit.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...